Gestion d’entreprise · Internal Audit and GRC

Gouvernance, risques et conformité appuyés sur des preuves, pas sur une présentation

The GRC layer on top of Compliance Control: an audit universe prioritized by risk, an annual plan approved by the committee, engagements with an audit program and reviewed working papers, findings with a management action plan and follow-up, three lines of defense declared, key risk indicators with risk appetite thresholds read from the real operating modules, and the ISO 27001, COSO and SOX libraries mapped onto the controls the company already has.

O problema e a saída

As dores que Internal Audit and GRC resolve todos os dias

Se alguma dessas situações parece familiar, é porque elas se repetem em quase toda empresa de formatura, até o sistema certo entrar em cena.

A dor

Internal audit is a spreadsheet of loose findings, and nobody knows whether the annual plan was carried out.

Com o Partiu Formatura

An audit universe with risk by process, an annual plan that is versioned and approved, engagements with status and plan execution measured on the dashboard.

A dor

The finding is written down, the manager agrees in the meeting and six months later nothing has changed.

Com o Partiu Formatura

A finding with a recommendation, a management action plan, a deadline and an owner, turning into an action in the same remediation flow Compliance already uses, with automatic follow-up and overdue alerts.

A dor

The person testing the control belongs to the same area that performs the control.

Com o Partiu Formatura

Independence checked through the segregation of duties that already exists: an auditor does not run procedures over controls in their own area, and any exception has to be recorded.

A dor

The board asks for risk indicators and gets opinions painted in traffic-light colors.

Com o Partiu Formatura

Indicators calculated from named formulas in code, reading overdue receivables, chargebacks, serious incidents, turnover, accidents and critical nonconformities, with risk appetite and tolerance declared.

A dor

Certification asks for the Statement of Applicability, and it gets assembled by hand every time.

Com o Partiu Formatura

ISO 27001, COSO and SOX libraries loaded per company and mapped to the internal controls, with the statement generated from the matrix and an explicit exception for any item excluded without justification.

Na prática

Exemplos reais de como Internal Audit and GRC trabalha por você

Situações do dia a dia de empresas de formatura, do problema ao resultado, usando os módulos que você vê nesta página.

01

A risk-based annual plan

O cenário

The company has to decide what to audit this year with the team it has.

Com o sistema

The audit universe is scored for inherent risk by process and business unit. The plan is built from that prioritization, versioned and approved on the committee agenda.

O resultado

The choice of what to audit is documented, and plan execution becomes a metric for the period.

02

An audit engagement in accounts payable

O cenário

The auditor has to prove what was tested, with the sample and the evidence.

Com o sistema

The engagement has an audit program with procedures, working papers with the sample, attached evidence, a conclusion and review by someone else. A finding becomes an action with an owner and a deadline.

O resultado

The report comes out with a complete trail, and follow-up chases on its own once the deadline passes.

03

A risk indicator breaching the appetite

O cenário

Overdue receivables go past the limit the board accepted.

Com o sistema

The daily measurement compares the value against appetite and tolerance. Out of range, continuous monitoring raises an alert and the board dashboard shows the trend.

O resultado

The conversation in the meeting starts from the number and the time series, not from this month's impression.

Como funciona

O caminho que a informação faz em Internal Audit and GRC

Cada etapa é um módulo de verdade, e o que sai de uma entra na outra sem ninguém digitar de novo.

  1. 1UniverseProcesses and business units are scored for risk, and the annual plan comes out of that prioritization.
  2. 2ApprovalThe committee approves the plan, and the approval is recorded on the agenda.
  3. 3ExécutionThe engagement runs with an audit program, working papers and independent review.
  4. 4RemédiationThe finding becomes an action with an owner and a deadline, chased through follow-up.
  5. 5Reddition des comptesIndicators, plan execution and open findings go to the board dashboard.

Módulo por módulo

Tudo o que existe em Internal Audit and GRC

7 módulos e 35 recursos nesta página, o mesmo cadastro de turma, formando e evento sustentando todos eles.

Audit Universe and Annual Plan

What can be audited, and what will be audited this year.

  • Processes and business units with inherent risk and last audit date
  • Risk-based prioritization feeding the annual plan
  • A plan that is versioned, approved and tracked by execution
  • Quality audits appearing in the universe, without being moved out of their module
  • An auditor register with home area and conflicts of interest

Engagements and Working Papers

The test that happened, with the proof that it happened.

  • Engagement with scope, period, team and status
  • An audit program with procedures by control objective
  • Working paper with sample, evidence, conclusion and reviewer
  • A reviewer different from the preparer, enforced by the system
  • Engagement closure blocked while a working paper is unreviewed or a finding has no action plan

Findings and Follow-up

What was found turns into change, with a deadline.

  • Finding with severity, recommendation and management action plan
  • Action created in the same Compliance remediation flow
  • Status read from the action itself, with no parallel tracking
  • Overdue finding alerts in continuous monitoring
  • Report and opinion going onto the committee agenda

Three Lines of Defense

Who performs, who monitors and who audits, declared.

  • Line of defense declared on the control, the risk and the test
  • The tester's area recorded on the effectiveness test
  • An auditor barred from testing a control in their own area
  • Exceptions allowed, but recorded with a justification
  • Independence visible in the report, without relying on trust

Key Risk Indicators

Risk measured with data from the system itself.

  • Named formulas in code, reading installments, chargebacks, incidents, HR, occupational health and safety and quality
  • Appetite and tolerance per indicator, set by the company
  • Daily measurement with a time series and a calculated trend
  • An automatic alert when the indicator moves out of range
  • A missing module returns an indicator with no basis, instead of a misleading zero

Frameworks and Statement of Applicability

The standard tied to the control you already have.

  • ISO 27001, COSO and SOX libraries loaded per company
  • Mapping of several requirements onto the same internal control
  • Coverage per framework calculated from the matrix
  • Statement of Applicability generated, flagging any exclusion made without justification
  • Lives alongside the existing libraries for LGPD (Brazilian data protection law), labor, occupational health and safety, tax and integrity

Board Dashboard

The snapshot that goes to the meeting, with its date and its source.

  • Residual risk heat map, showing the effect of the controls
  • Trend of the key risk indicators over the period
  • Audit plan execution and overdue findings
  • Business continuity maturity and the integrity program score
  • PDF export kept along with the period's snapshot

Encontre o plano ideal para Internal Audit and GRC

Compare os módulos e escolha a configuração que acompanha sua operação.